Key Takeaways
A QR code is nothing more than a URL, a wallet address, or a WalletConnect pairing string encoded as a scannable grid of squares. Everything a typed link can do, a QR code can also do — including leading to a phishing site or a malicious wallet-connection request. The difference is what makes QR codes a distinct attack surface worth its own guide: with a typed or pasted link, you can hover, zoom in, or read the domain character by character before you click. With a QR code, that inspection step is gone by default. You commit to a destination the instant your camera decodes the pattern, unless your scanning tool specifically shows you a preview first.
Direct answer: QR code phishing ("quishing") works because a QR code hides its destination until scanned, and because crypto legitimately uses QR codes everywhere — wallet addresses, WalletConnect pairing, exchange logins, in-person payments — which makes a malicious code blend into normal behavior instead of standing out. Attackers exploit this by physically swapping real codes for fake ones on event signage and payment terminals, embedding malicious codes in "verify your wallet" or "claim your tokens" emails and DMs, and presenting fake WalletConnect pairing codes that connect your wallet to an attacker's interface instead of the one you meant to use.
- A QR code is just an encoded link or connection request — it carries the same risks as a typed URL, plus the added risk that you can't preview the destination before scanning.
- Crypto's legitimate, constant use of QR codes for wallet addresses, WalletConnect, and logins is exactly what makes a malicious one easy to overlook.
- Physical QR codes on signage, flyers, and payment terminals can be covered with an attacker's sticker without anyone noticing at a glance.
- A fake WalletConnect QR pairing can connect your wallet session to an attacker-controlled dApp interface rather than the legitimate site you intended to use.
- "Scan to verify" or "scan to claim" QR codes in unsolicited emails and DMs deserve exactly the same suspicion as any other phishing link.
- A scanner or camera app that previews the decoded URL before opening it restores the inspection step a QR code otherwise removes.
Why QR Codes Are a Distinct Phishing Vector
Ordinary link-based phishing already has a well-known defense: look at the URL before you click it. A misspelled domain, an unfamiliar top-level extension, or a URL that doesn't match the sender's claimed identity are all things a careful reader can catch in the second or two before committing to a click. That defense depends entirely on the link being visible as text — something your eyes can parse — before any navigation happens.
A QR code breaks that defense structurally, not just practically. The information encoded in the pattern of black-and-white squares is unreadable to a human eye; it only becomes a URL, a wallet address, or a connection string after a camera or scanner decodes it, and by the time most phones or apps show you anything, they've often already opened the link or handed it to a browser. The inspection step link-based phishing training relies on simply doesn't exist by default for a QR code. You're not deciding whether to visit a destination you can read — you're deciding whether to trust a pattern you can't read at all, based only on where the code was printed or who appeared to send it.
The second half of what makes QR codes distinct in crypto specifically is how pervasive and legitimate their use already is. Sharing a wallet address by QR code avoids the error-prone process of typing or reading aloud a 42-character hexadecimal string. WalletConnect, the protocol that lets a mobile wallet approve actions on a desktop dApp, is built entirely around scanning a QR code to establish the session. Exchanges routinely offer QR-code logins and two-factor authentication setup. In-person crypto payments — a vendor at a conference, a tip jar at a meetup — are almost always QR-code driven, since typing out a full wallet address by hand isn't realistic. None of this is unusual or suspicious on its own; it's simply how crypto works day to day. That ubiquity is precisely the cover a malicious QR code exploits. A code asking you to scan and connect your wallet doesn't stand out in a space where that request is completely ordinary, which is exactly why it doesn't trigger the same instinctive caution a stranger asking for your seed phrase would.
Common Quishing Attack Patterns
Swapped or overlaid physical QR codes
Printed QR codes are trivially easy to replace. A sticker printed with a malicious code, sized to match the original, can be placed directly over a legitimate code on event signage, a sponsor banner, a printed flyer, or a payment terminal in the time it takes to walk past and press it down. Nobody watching a busy conference floor or a crowded meetup room is likely to notice a sticker being applied, and once it's there, everyone who scans it afterward is scanning the attacker's destination instead of the intended one. This pattern doesn't require compromising any account, cloning any website beyond what's necessary for the landing page, or gaining any special access — it only requires physical proximity to a printed code for a few seconds.
Malicious QR codes in phishing emails and DMs
Email and direct-message phishing has increasingly shifted toward embedding a QR code as an image rather than a clickable text link, partly because it's a novel enough format that some recipients haven't yet built the same reflexive suspicion toward it, and partly because a QR code image is harder for automated email-security scanners to flag than a visible malicious URL, since the destination isn't present as scannable text in the message body. The framing is almost always the same regardless of channel: a claim that something needs "verification," that funds or tokens are waiting to be "claimed," or that account access will be lost unless the code is scanned promptly. The QR code itself decodes to a phishing site built to harvest a seed phrase, request a malicious wallet connection, or capture exchange login credentials.
Fake WalletConnect pairing codes
WalletConnect's actual pairing flow is simple and, on its face, hard to distinguish visually from a fake one: a dApp interface displays a QR code, the user opens their wallet app and scans it, and a connection request appears asking to approve the session. Nothing about a QR code's appearance reveals whether the dApp presenting it is the legitimate site the user intended to visit or a cloned interface hosted on a look-alike domain. If the underlying page is fake — reached through a phishing link, a swapped physical code, or a manipulated search result — the WalletConnect QR code it displays will pair the wallet with the attacker's session instead. The wallet-side approval prompt is the last real checkpoint in this flow, and it's often skimmed quickly because the pairing step itself feels routine.
Worked Example: A Swapped QR Code at a Crypto Meetup
Hypothetical, generic example — for education only. Not based on any specific real event or organization.
Picture a mid-sized crypto meetup held at a co-working space, the kind of recurring local event with fifty to a hundred attendees, a couple of sponsor tables, and a printed schedule taped to the wall near the entrance. One sponsor table is staffed by a small project handing out merchandise and running a simple on-site promotion: attendees who scan a QR code on the table's tent card and connect a wallet get a small amount of a test token dropped into their address, a common and entirely ordinary practice at events like this.
Sometime between setup and the event's actual start, an attacker who walked in as a regular attendee approaches the table during a lull, and in a few seconds presses a pre-printed sticker directly over the tent card's original QR code. The sticker is sized and printed to closely match the original — same rough dimensions, a plausible white border — and from a normal viewing distance, nothing about it looks obviously out of place. The sponsor staff, focused on conversations with attendees rather than continuously monitoring their own signage, don't notice the swap.
Over the next hour, a steady stream of attendees walk up, scan the code, and are taken to a site that looks essentially identical to the sponsor's real promotional page — same logo, same color scheme, likely built by directly copying the visible assets from the real site. The page asks visitors to connect a wallet to "receive your drop," a request that matches exactly what the sponsor's real promotion was already asking for, so it raises no suspicion. Once connected, the site requests a signature framed as claiming the promotional token. In reality, the signature is a broad approval over an existing, more valuable token already sitting in some attendees' wallets. Nothing appears to go wrong at the moment of signing — no error, no obvious drain — which is exactly why several attendees don't realize anything happened until hours or days later, when assets move out of their wallets at a time of the attacker's choosing.
The tell here wasn't available by reading the QR code itself — it never is. It was available in exactly two other places: physically noticing that the sticker on the tent card looked slightly different from the surrounding printed material (a faint edge, a mismatched paper texture), and treating the wallet-connect and signature prompts with the same scrutiny that any unfamiliar site deserves, regardless of how legitimate the surrounding table and staff appeared. A QR scanner that previewed the destination URL before opening it would also have surfaced a domain that didn't match the sponsor's known site, catching the problem before any page even loaded.
"Scan to Verify" and "Scan to Claim" Deserve the Same Suspicion as Any Phishing Link
It's worth stating plainly: a QR code is not a different category of thing from a link. It is a link, encoded differently. Every heuristic that applies to an unsolicited email or DM containing a suspicious URL applies identically to one containing a suspicious QR code — an unexpected "verify your account" request, urgent language about expiring access, a claim that funds or tokens are waiting, or a sender you don't recognize are all the same red flags regardless of whether the malicious destination is presented as blue underlined text or a scannable square.
What changes with a QR code is only the defender's side of the equation, and it changes for the worse. A suspicious text link can be inspected — hovered over on desktop, long-pressed on mobile, or copied and read character by character — entirely before deciding whether to visit it. A QR code, scanned with a default camera app on many phones, frequently opens the decoded link immediately or with only a single, easy-to-dismiss tap, without ever displaying the underlying URL in a form most people stop to read. The QR format doesn't make the underlying phishing attempt more sophisticated; it just removes the cheapest, most widely taught defense against it. Any "scan to verify," "scan to claim," or "scan to unlock" QR code arriving unsolicited, whether by email, DM, text message, or printed mail, should be treated with exactly the skepticism a matching text link would get — which, in nearly every legitimate context, means not scanning it at all and instead navigating independently to the account or site in question through a known, bookmarked URL.
Practical Defenses Against QR Code Phishing
None of the defenses below require special technical skill, and most take only a few extra seconds compared to scanning blindly.
Practical checklist
- Use a QR scanner or camera app that shows a URL preview before navigating anywhere, rather than one that opens the link automatically; many phone camera apps and dedicated scanner apps support this, and it's worth confirming which behavior yours defaults to.
- Read the previewed URL the same way you'd read any link: check the domain character by character against the site you expect, watching for look-alike substitutions, extra hyphens, or unfamiliar top-level extensions.
- Physically inspect any printed QR code for signs of a sticker overlay — a different paper texture or finish, a visible edge or lifted corner, slightly mismatched sizing or alignment against the surrounding printed material, or a placement that looks added rather than original to the design.
- Treat any unsolicited "scan to verify," "scan to claim," or "scan to unlock" QR code in an email, DM, or text exactly as you would a suspicious link: don't scan it, and instead navigate independently to the account or site through a known URL or bookmark.
- When scanning a WalletConnect pairing code, confirm the dApp name, domain, and requested permissions shown in your wallet's connection prompt actually match the site you intentionally opened, before approving the session.
- For high-stakes scans — connecting a wallet, entering credentials, or anything financial — prefer typing a known URL directly over scanning a code you encountered unexpectedly, even if the code appears to be posted somewhere official-looking.
- If an event or venue's signage looks like it could plausibly be tampered with, ask staff to confirm the correct link or QR code verbally rather than relying on the printed material alone.
Common mistake
The common mistake isn't a lack of general caution — it's applying real caution to typed links while giving QR codes a pass, simply because they're unfamiliar enough not to trigger the same trained skepticism yet. A QR code should get at least the same scrutiny as a text link, not less, precisely because it's harder to inspect before committing to it.
Common Mistakes
- Scanning QR codes from unverified physical locations without checking the destination first. A code posted on public signage, a flyer, or a payment terminal carries no inherent guarantee that it hasn't been altered since it was originally placed.
- Scanning unsolicited QR codes from digital sources without applying link-phishing habits. An email or DM containing a QR code should trigger exactly the same review process as one containing a text link, not a lighter one.
- Not noticing a sticker overlay on a physical QR code. Attackers rely on nobody stopping to look closely at printed material that otherwise looks routine and unremarkable.
- Letting a scanner app auto-navigate instead of previewing the URL. The single most useful technical defense against quishing — seeing the destination before visiting it — depends entirely on using a scanner configured to show that preview.
- Approving a WalletConnect session without checking the dApp name and domain shown in the wallet prompt. The pairing step feels routine precisely because it's used so often for legitimate connections, which makes it easy to approve without reading what's actually being confirmed.
- Assuming an official-looking or professionally printed QR code can't be fake. Print quality and professional design say nothing about whether a code is the original one or a replacement placed afterward.
Misconceptions Versus Reality
| Misconception | Reality |
|---|---|
| QR codes are inherently more trustworthy than typed URLs because they're used for official things like WalletConnect | The legitimacy of the QR code mechanism says nothing about whether any individual code is trustworthy; WalletConnect's protocol being legitimate doesn't stop a fake dApp from displaying its own malicious pairing code |
| Scanning a QR code is inherently more dangerous than clicking a link, since it could contain malware | A QR code is almost always just an encoded URL or connection string, not executable code; the danger comes from where the link leads and what you do after, the same as any other phishing link |
| If a QR code is printed on official-looking signage or professional materials, it must be genuine | Print quality and placement say nothing about authenticity; a sticker printed to closely match the original can be placed over a legitimate code in seconds |
| My phone would warn me if a QR code led somewhere dangerous | Most default camera apps decode and offer to open a link with no safety evaluation at all; a URL preview only appears if the specific scanner app you're using is built to show one |
| A QR code in an email from a company I recognize must be safe to scan | Sender identity in email and DMs is trivially spoofable, and QR-code phishing is increasingly used specifically because it's less likely to be flagged by automated security scanning than a visible malicious link |
| Approving a WalletConnect session is a low-risk, routine action | A WalletConnect approval can grant a connected dApp interface the ability to request signatures and transactions from your wallet; approving a session with an attacker-controlled interface carries the same risk as connecting to any other malicious site |
Prevention Checklist
These habits address QR code phishing specifically, but they build directly on the same domain-verification and cautious-signing habits that defend against phishing generally.
Practical checklist
- Default to a scanner or camera app that previews a decoded URL before opening it, and get in the habit of actually reading that preview.
- Never scan a QR code specifically to "verify," "claim," or "unlock" something in response to an unsolicited email, DM, or message; navigate to the relevant account or site independently instead.
- Physically inspect printed QR codes at events, on payment terminals, and on public signage for signs of a sticker overlay before scanning, especially where money or a wallet connection is involved.
- Check the dApp name, domain, and requested permissions shown in a wallet's connection prompt before approving any WalletConnect pairing, regardless of how the QR code was presented.
- Prefer typing a known URL directly, or using a saved bookmark, over scanning a code for any high-stakes action involving a wallet connection, login, or payment.
- Periodically review and revoke unused or unrecognized WalletConnect sessions and token approvals using a reputable approval-checking tool.
- Never enter a seed phrase or private key on any page reached by scanning a QR code, regardless of how official the surrounding branding looks.
Risks, Limitations, and Exceptions
- Not every scanner app or phone camera supports a URL preview before navigating; behavior varies by device, operating system version, and the specific app used.
- A sticker overlay on a physical code is not always visible in poor lighting, from a distance, or when the attacker uses higher-quality printing materials than assumed here.
- Legitimate events and businesses do sometimes update or reprint their own QR codes for ordinary reasons, which can make a genuine change superficially resemble tampering; when in doubt, verifying with staff directly is more reliable than visual inspection alone.
- WalletConnect connection prompts vary in detail and clarity across different wallet apps, and some provide less information about the requesting dApp than others.
- Revoking a session or approval after a malicious connection has already been used to sign a transaction does not undo that transaction; revocation only prevents further access going forward.
- This guide describes common quishing patterns and does not cover every technical variant; attackers continue to adapt these tactics as awareness of them spreads.
Tool Opportunity
A dedicated Swoopr tool should help readers safely preview what a QR code decodes to before committing to it, without exposing them to the destination it points to.
Recommended inputs: an uploaded photo or live camera capture of a QR code, and optionally the context in which it was encountered (email, DM, physical signage, payment terminal).
Expected outputs: the fully decoded URL or connection string displayed as plain, readable text without auto-navigating to it, a domain comparison against commonly impersonated or previously reported phishing domains where available, and a plain-language flag distinguishing a standard web link from a WalletConnect-style pairing request.
Validation requirements: never automatically open or navigate to the decoded destination, never request or store wallet credentials as part of the scan, clearly label domain-comparison results as heuristic signals rather than a definitive safety verdict, and direct ambiguous or unfamiliar domains toward manual verification through the entity's own official channels.
Sources
- Federal Trade Commission, "Scammers hide harmful links in QR codes," consumer.ftc.gov — a consumer advisory describing how QR codes are used to redirect victims to phishing and credential-harvesting sites, including physical code-swapping tactics.
- Cybersecurity and Infrastructure Security Agency (CISA), "Scanning QR Codes Can Be Risky Business," cisa.gov — federal guidance on the security risks of scanning unfamiliar QR codes and recommended precautions.
- WalletConnect, WalletConnect Documentation, docs.walletconnect.com — the protocol's own technical documentation describing how QR-based wallet-to-dApp pairing sessions work.
Frequently Asked Questions
What is QR code phishing ("quishing")?
QR code phishing, sometimes called quishing, is a phishing attack delivered through a QR code instead of a typed link. The code encodes a URL just like any other link, but because a QR code is a grid of black-and-white squares, a human can't read where it leads before scanning it, which removes the visual inspection step that catches many ordinary link-based phishing attempts.
Why are QR codes specifically dangerous in crypto?
Crypto uses QR codes constantly for entirely legitimate purposes: sharing a wallet address, pairing a wallet with a dApp through WalletConnect, logging into an exchange, or setting up two-factor authentication. That legitimate, everyday use is exactly what attackers rely on, because a QR code asking you to "scan to connect your wallet" or "scan to verify" looks completely normal in a space where that request is routine.
Can a QR code hack my phone or wallet just by scanning it?
In the overwhelming majority of cases, no. A QR code is almost always just an encoded URL or a WalletConnect pairing string, not executable code, so scanning it alone typically does nothing beyond opening a link or presenting a connection request. The risk comes from what happens after the scan: visiting a phishing site, approving a malicious WalletConnect session, or entering a seed phrase on a fake page.
How can I tell if a physical QR code has been tampered with?
Look for a sticker with slightly different paper stock, adhesive edges, printing quality, or alignment compared to the surface it's on, since attackers frequently print a malicious code on a sticker and place it directly over the real one. Also compare the code's surrounding text or branding to what you'd expect, and if anything is possible, verify the destination through a scanner that previews the URL before your phone navigates anywhere.
Is scanning a WalletConnect QR code always safe?
The WalletConnect protocol itself is a legitimate, widely used standard for pairing a wallet with a dApp, but the QR code presenting a pairing request can originate from a malicious or cloned interface just as easily as a real one. Always confirm the dApp name, URL, and requested permissions shown in your wallet's connection prompt match the site you intentionally navigated to before approving.
What should I do if I scanned a suspicious QR code?
If a page opened but you didn't enter any information, connect a wallet, or approve anything, close the page and avoid interacting with it further. If you connected a wallet or approved a WalletConnect session, immediately review and revoke the resulting session and any token approvals using a reputable approval-checking tool, and treat any wallet used to enter a seed phrase on the page as compromised.
Which Swoopr resource helps verify a link before scanning or clicking it?
The guide on how to verify a legitimate site covers the domain-checking habits that apply directly to whatever URL a QR code decodes to, and the broader Phishing & Wallet Drainers hub covers the underlying phishing and wallet-drainer mechanics a malicious QR code is typically used to deliver.
Conclusion
QR codes aren't a separate class of threat from ordinary phishing links — they're the same threat wearing a format that happens to remove your ability to inspect it first. That single difference is enough to make quishing effective even against people who'd never click an obviously suspicious text link, simply because the destination stays hidden until it's already too late to change course. The fix isn't avoiding QR codes, which are genuinely useful and deeply embedded in how crypto works day to day; it's restoring the inspection step wherever possible — a scanner that previews the URL, a careful look at printed signage for signs of tampering, and the same skepticism toward "scan to verify" that a matching typed link would get. Use this page alongside the broader Phishing & Wallet Drainers hub for the domain-verification and wallet-approval habits that apply across phishing generally, not just to QR codes.
Related Reading
- Phishing & Wallet Drainers — the parent hub covering phishing tactics, wallet drainers, and related scam patterns.
- How to verify a legitimate site — the domain and site-verification habits that apply to whatever destination a QR code decodes to.
- Typosquatting and fake domains — how to spot the look-alike domains that malicious QR codes and swapped physical codes commonly lead to.
- Malicious dApp connections — how a fake or cloned dApp interface, including one reached through a scanned QR code, can drain a connected wallet.
- Fake airdrop phishing — the claim-site and broad-approval mechanics that quishing scams frequently reuse once a victim lands on the destination page.
- Hot wallets vs. cold wallets — how storage choice affects exposure to drainer approvals from a malicious QR-code destination.